Transparency register
Sub-processors and service providers.
These providers are authorised to support Worka. The particular providers that receive Customer Personal Data depend on the features and channel a customer uses.
Current authorised providers
| Provider | Purpose and data | Likely processing location / safeguard |
|---|---|---|
| Netlify, Inc. | Marketing-site hosting, delivery and security logs; visitor IP and request/device data. | UK, EEA and US; adequacy or UK transfer terms where required. |
| Vercel, Inc. | Customer console and onboarding hosting; account, onboarding and technical data. | UK, EEA and US; adequacy or UK transfer terms where required. |
| Supabase, Inc. | Database, authentication and storage; account, configuration and service data. | Configured EEA region where available; support may involve restricted transfers under UK transfer terms. |
| Hetzner Online GmbH | Isolated Worka runtime and backups; Customer Content, configuration and operational logs. | EEA data centres; UK adequacy regulations. |
| Stripe group companies | Checkout, subscription billing, tax and fraud prevention; identity, contact, payment and transaction data. Stripe may also act as an independent controller. | UK, EEA and global Stripe infrastructure; Stripe’s applicable UK transfer safeguards. |
| OpenAI, L.L.C. / OpenAI group | AI model inference and speech transcription; relevant instructions, content and outputs. Business/API data controls are used so content is not used to train general models. | May include US; UK Addendum/IDTA or other lawful safeguard. |
| Anthropic, PBC | Fallback AI model inference; relevant instructions, content and outputs under commercial API terms. | May include US; UK Addendum/IDTA or other lawful safeguard. |
| Google LLC / Google Cloud | Fallback AI model inference; relevant instructions, content and outputs under business API terms. | May include EEA and US; adequacy and/or UK transfer terms. |
| Amazon Web Services, Inc. and/or Resend, Inc. | Transactional and Worka email delivery; sender/recipient details, message content, delivery and security logs. Only the configured email provider is used. | Configured UK/EEA where available; UK transfer terms for other access. |
| Telegram Messenger Inc. | Optional customer-selected messaging channel; Telegram account identifiers, messages, files and delivery metadata. Telegram also acts under its own terms. | Telegram’s global infrastructure; use is optional and email is available. |
A provider appearing here is authorised, but does not mean every customer’s information is sent to that provider. We minimise the content shared for each request and use business/API accounts with contractual data controls.
Changes and objections
Active customers receive at least 14 days’ notice before a new sub-processor begins processing Customer Personal Data, except where an urgent replacement is needed to protect security or avoid service interruption. A customer may object during that period on reasonable, evidenced data-protection grounds under the DPA.
Questions
For more information about a provider, processing location or transfer safeguard, email hello@asistu.ai.